ApolloMD Data Breach Exposes Social Security Numbers and Health Records

Healthcare data breach illustration
Breach Discovery: May 2025Breach Notification: September 2025

What Happened in the ApolloMD Data Breach?

In July 2026, ApolloMD Business Services agreed to pay $4.02 million to settle a class action lawsuit over a ransomware attack that exposed patient data. This settlement resolves claims tied to a breach first identified in May 2025. Because the case has now reached preliminary court approval, affected individuals have a real opportunity to file for compensation.

ApolloMD provides administrative and practice management services to healthcare providers across the country. As a result, the company holds sensitive patient information on behalf of its provider clients. According to court filings, unauthorized access to its network occurred in May 2025, over a short window of time before ApolloMD detected the intrusion.

A forensic investigation later confirmed that a ransomware actor infiltrated the network and potentially copied files containing protected health information. The Qilin ransomware group claimed responsibility for the attack. This means the incident was not simply a system outage; instead, it involved an active criminal effort to steal data for extortion purposes.

Following the discovery, ApolloMD launched an investigation to determine exactly which files and individuals were affected. That review took time, which is why notification letters went out in two separate waves. The first batch was mailed in September 2025, and a second wave followed in March 2026 as the investigation identified additional affected people.

Who was affected?

The breach affected patients of the healthcare providers that rely on ApolloMD for practice management and administrative support. Because ApolloMD works with multiple physician groups, the exposure reached a wide network of patients rather than a single clinic or hospital system.

ApolloMD reported the breach to the HHS Office for Civil Rights as affecting 626,540 individuals. This is a large-scale healthcare breach by any measure. The affected population likely spans multiple states, since ApolloMD supports provider clients across a broad service area. There is no indication in the available information that the breach targeted a specific age group, so both adult and potentially pediatric patient records may be included.

What Information Was Potentially Exposed?

The forensic investigation found that the attacker accessed files containing several categories of sensitive personal and medical information. Not every individual had the same data exposed, but the breach notice describes the following types of information as compromised.

  • Full names
  • Dates of birth
  • Health information
  • Health insurance information
  • Social Security numbers (for some individuals)

This combination of data creates serious risk. When Social Security numbers are exposed alongside dates of birth, criminals gain nearly everything they need to open new credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name. Because health information was also involved, victims face an additional threat: medical identity theft, where someone uses stolen insurance details to receive treatment or submit fraudulent claims.

Medical identity theft can be especially damaging because it may corrupt a victim’s own medical records with inaccurate information. This can lead to billing disputes, denied claims, or even incorrect treatment decisions down the line. As a result, victims of this breach should treat both their financial and medical accounts as potentially at risk, not just one or the other.

What is the company doing?

After identifying the intrusion, ApolloMD engaged forensic investigators to determine the scope of the attack and secure its network. The company then notified regulators and affected individuals in stages as its review progressed, sending the first notification letters in September 2025 and a second round in March 2026.

As part of the settlement, ApolloMD has agreed to fund a $4,020,000 settlement pool, even though the company denies any wrongdoing or liability. In addition, all class members are entitled to a one-year membership in a CyEx medical data monitoring service. This service is designed to help detect potential misuse of medical and personal information going forward.

What Should Affected Individuals Do?

File a Claim Before the Deadline

Affected individuals should consider filing a claim under the settlement soon, since deadlines are approaching quickly. Claims must be submitted by September 30, 2026, and anyone who wishes to object or opt out must do so by August 31, 2026.

Class members can choose between two payment options. One option allows reimbursement of documented, unreimbursed losses up to $5,000 per person. Alternatively, claimants may request a pro rata cash payment, currently estimated at $75, though this amount may rise or fall depending on how many people file claims.

Enroll in the Free Monitoring Service

Everyone affected by this breach qualifies for a free one-year membership to the CyEx medical data monitoring service. This benefit does not require filing a cash claim, so affected individuals should sign up regardless of which payment option they choose.

Medical data monitoring works differently from standard credit monitoring because it watches for misuse of health insurance and medical identifiers. Because health information was exposed in this breach, this added layer of protection is particularly relevant and should not be skipped.

Monitor Credit Reports and Financial Accounts

Since Social Security numbers were exposed for some individuals, affected people should check their credit reports regularly for unfamiliar accounts or inquiries. Free credit reports are available from each of the three major credit bureaus, and reviewing them every few months can help catch fraud early.

In addition, individuals should watch bank and credit card statements closely for any unauthorized charges. If something looks off, contacting the financial institution immediately can limit the damage and start the dispute process sooner.

Consider a Credit Freeze or Fraud Alert

Because Social Security numbers are among the most valuable pieces of data for identity thieves, affected individuals may want to place a credit freeze with the major credit bureaus. A freeze blocks new creditors from accessing your credit file, which makes it much harder for someone to open accounts in your name.

Alternatively, a fraud alert requires creditors to take extra verification steps before approving new credit. This option is less restrictive than a freeze but still offers meaningful protection. Either step is free and can typically be set up online or by phone.

Stay Alert for Phishing Attempts

Following any healthcare data breach, scammers often send phishing emails or calls pretending to be from the breached company or a monitoring service. Affected individuals should never click links or share personal information in response to unsolicited messages.

Instead, verify any communication by contacting the organization directly through a known, official phone number or website. Because this breach involved health insurance details, phishing attempts may specifically reference medical claims or coverage, so extra caution is warranted when reviewing such messages.



Related Data Breaches